Securing app access on a user basis

We are wondering what status of limiting users to certain permissions such as viewing an app and the ability to ssh into it?

Our use case is that we have production data that our entire org shouldn’t have access to, but as it is today being able to SSH with flyctl gives any member or admin access to ENV vars and the apps console. Is there anything in the roadmap to limit this access?


Certainly seems like it’s in the roadmap, but not sure when e.g:

